CVE-2010-1871
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 83% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-917
מוצרים מושפעים
redhat: jboss enterprise application platform; redhat: enterprise linux; netapp: oncommand balance; netapp: oncommand insight; netapp: oncommand unified manager
קישורים
- http://www.vupen.com/english/advisories/2010/1929 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/1929 Broken LinkVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.html Broken Link
- http://www.redhat.com/support/errata/RHSA-2010-0564.html Broken Link
- http://www.securityfocus.com/bid/41994 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1024253 Broken LinkThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=615956 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60794 Third Party AdvisoryVDB Entry
- https://security.netapp.com/advisory/ntap-20161017-0001/ Third Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.html Broken Link